Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
CA
CRI Advantage
Cyber Analyst- Level 3
Career Insights for Incident Analyst / Responder
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Idaho data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An Incident Analyst or Responder investigates an IT-related incident: an unplanned interruption to a service, a reduction in the quality of a service, or an event that has not yet impacted the service to the customer. Works to restore a normal service operation as quickly as possible and to minimize the impact on business operations.
$121,603 / year median in Idaho
+14% projected growth
Job Description
Cyber Analyst- Level 3 CRI Advantage $80.00 - $90.00 / hr relocation assistance United States, Idaho, Idaho Falls 520 Energy Drive (Show on map) Aug 05, 2026 Description In this role, the selected candidate will design, build, and tune detections that identify malicious activity across our environment, working at the intersection of security analysis, data engineering, and machine learning. We are looking for a candidate who lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts. Responsibilities
- Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources.
- Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES).
- Leverage the Splunk App for Data Science and Deep Learning (DSDL) to operationalize machine learning models for anomaly detection and advanced threat identification.
- Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches.
- Map detection coverage to the
MITRE ATT&CK
framework and identify gaps in visibility.- Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections.
- Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management.
- Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content.
- Create documentation, runbooks, and detection specifications to support downstream analysts. Requirements
- Be willing to relocate to Idaho Falls, Idaho. (Relocation assistance may be available)
- Have a current "L" or "Q" clearance.
- Have the following required skillsets: o Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization.
MITRE ATT&CK
framework and detection engineering methodology. o Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.). Preferred Qualifications- Experience with detection-as-code practices and tools (Git, CI/CD pipelines).
- Proficiency in Python for data processing and model development.
- Knowledge of SOAR platforms and detection automation.
- Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.).
- Prior experience in a SOC, threat hunting, or incident response role.